WrapUp

Privacy Policy

WrapUp · Alpha · last updated August 29, 2026

Introduction

This Privacy Policy describes how WrapUp ("WrapUp," "we," "us," or "our") collects, uses, discloses, and protects information when you access or use our website and application at wrapup.studio and related services (collectively, the "Service").

By using the Service, you acknowledge that you have read and understood this Privacy Policy. If you do not agree, do not use the Service.

Alpha software notice

WrapUp is currently offered as pre-release Alpha software. Features, data practices, and third-party integrations may change without notice. During Alpha, the Service is provided on an "as is" and "as available" basis. Do not rely on the Service as your sole record of client work, financial records, or legally binding documents: maintain independent backups.

Information we collect

We collect information in the following categories:

Account and profile information. When you create an account, we collect your email address, display name, business name, creator type, and authentication credentials. Authentication is handled by Supabase Auth; we do not store your password in plain text. You may sign in with email and password or Google OAuth (when enabled).

Project and business data. When you use the Service, we store the content you enter or upload, including client names and contact details, project briefs, scripts, shot lists, production notes, deliverables, estimates, invoices, usage-rights fields, outreach drafts, and related metadata. When you are signed in, this data is synced to our Postgres database hosted on Supabase. A copy may also be stored locally in your browser (localStorage) for performance and offline resilience.

Creator kit and portfolio data. If you configure a public media kit, we store your bio, rate card, portfolio entries, social links, audience statistics, and booking contact information you choose to display.

Integration connection data. When you connect third-party accounts (Google Calendar, Notion, or Buffer), we store OAuth access tokens and, where applicable, refresh tokens. Tokens are encrypted at rest using AES-256-GCM before storage in our database. We also store non-sensitive connection metadata (such as connected workspace or account identifiers) and log connect, disconnect, and export events in an integration audit log.

Waitlist information. If you join a paid-tier waitlist, we collect your email address, selected tier, optional account association, and signup source.

Billing information. If you subscribe, Stripe processes your payment. We store your Stripe customer and subscription IDs, plan, and status so we can unlock the right features. We do not store full card numbers.

Usage and analytics data. We log product events (such as project creation, brief parsing, and feature usage) locally in your browser. When configured, we also send usage events and page views to PostHog, our analytics provider. When you are signed in, PostHog may associate events with your user ID and email address.

Technical and device data. We automatically receive certain technical information when you use the Service, including IP address, browser type, device type, operating system, referring URLs, and timestamps. This data may be collected by our hosting provider (Netlify), Supabase, PostHog, and similar infrastructure providers.

Communications. If you contact us by email, we collect the contents of your message and associated contact details.

How we use information

We use collected information to:

  • Provide, operate, maintain, and improve the Service
  • Authenticate users and manage accounts
  • Sync and store your project data across devices
  • Process briefs and generate production plans using AI providers
  • Connect to and act on your behalf with authorized third-party integrations (calendar, Notion export, Buffer scheduling)
  • Generate and serve public share links and creator kit pages you choose to publish
  • Analyze product usage to improve features and fix issues
  • Manage waitlists and communicate about Alpha access and future plans
  • Process paid subscriptions through Stripe when you subscribe
  • Respond to support requests and privacy inquiries
  • Detect, prevent, and address fraud, abuse, security incidents, and technical problems
  • Comply with applicable law and enforce our Terms of Use

We do not sell your personal information. We do not use your project content to train general-purpose AI models. Content you submit for AI-assisted features is transmitted to our configured AI provider(s) solely to generate responses for your session; we do not claim ownership of your content.

AI processing

WrapUp may send text you provide, such as client briefs, project context, questions, and outreach drafts, to third-party AI providers to extract project details, generate production plans, draft messages, and answer project questions. Depending on configuration, these providers may include Groq, Google Gemini, or OpenAI. If no external AI key is configured, processing may occur locally using rule-based heuristics without sending data to an external model.

AI output is suggestive only. We do not guarantee accuracy, completeness, or legal compliance of AI-generated content. You are responsible for reviewing all AI output before sharing with clients or relying on it for business or legal decisions. Do not submit confidential, regulated, or personally sensitive information you are not authorized to share with subprocessors.

Each AI provider maintains its own privacy policy and data handling practices. We encourage you to review their terms before using AI features.

Third-party integrations

When you authorize an integration, WrapUp accesses only the scopes you approve on the provider's consent screen:

  • Google Calendar: read upcoming events and create or delete events when you add calendar items through the Service
  • Notion: export project briefs to pages in workspaces you share with the integration
  • Buffer: schedule posts to channels on your connected Buffer account

OAuth tokens are stored encrypted in our database and are accessible only to server API routes: never exposed to your browser or other users. When you disconnect an integration, we delete stored tokens from our systems. Google Calendar tokens are also revoked with Google's API where supported. Content you created in third-party services (such as Notion pages) remains in those services under your control.

Public and shared links

The Service lets you generate tokenized links for invoices, estimates, deliveries, approvals, and creator media kits. Anyone with a valid link may view the content exposed through that link. Links are not indexed by us for public search, but they are not secret if forwarded. You are solely responsible for who you share links with and for the information you include in shared views.

Public creator kit pages (by token or custom slug) display the profile and portfolio information you configure. Do not publish information you do not want publicly accessible.

Cookies and similar technologies

We and our service providers use cookies, localStorage, and similar technologies:

  • Authentication cookies: maintain your signed-in session (Supabase Auth)
  • OAuth state cookies: secure integration connect flows (short-lived, httpOnly)
  • Analytics, PostHog may use cookies and localStorage when enabled
  • Local preferences: store app state, onboarding progress, and billing tier selections in your browser during Alpha

You can control cookies through your browser settings. Disabling cookies may limit certain features, including sign-in and integrations.

How we share information

We may share information in these circumstances:

  • Service providers: companies that process data on our behalf to host, store, authenticate, analyze, or deliver the Service (listed below)
  • Integration providers: when you connect Google, Notion, or Buffer, necessary data is exchanged to perform authorized actions
  • AI providers: when you use AI features, relevant text is sent to the configured provider
  • Legal and safety: if required by law, regulation, legal process, or governmental request, or to protect rights, property, or safety of us, users, or the public
  • Business transfers: in connection with a merger, acquisition, financing, or sale of assets, subject to customary confidentiality obligations

We do not share your project data with other WrapUp users.

Service providers (subprocessors)

We use third-party providers that may process personal information. Their locations and practices are governed by their own policies:

  • Supabase: authentication and Postgres database hosting
  • Netlify: application hosting and content delivery
  • PostHog: product analytics (when NEXT_PUBLIC_POSTHOG_KEY is configured)
  • Groq, Google (Gemini), OpenAI, AI inference (as configured)
  • Google, Google sign-in and Google Calendar API (when you use those features)
  • Notion, workspace export (when you connect Notion)
  • Buffer, social scheduling (when you connect Buffer)
  • Stripe: paid subscriptions and invoices (when you subscribe)

We require service providers to handle data only as needed to perform services for us, but we do not control their independent practices.

Data retention

We retain account and project data while your account is active and as needed to provide the Service. Integration tokens are deleted when you disconnect. Integration audit events may be retained for security and troubleshooting for a limited period.

Waitlist emails are retained until you request deletion or we no longer need them for the stated purpose. Local browser data persists until you clear site data or we migrate storage keys.

We may retain certain information as required by law, to resolve disputes, enforce agreements, or for legitimate business records. Backup copies may persist for a limited time after deletion.

Security

We implement reasonable administrative, technical, and organizational measures designed to protect information, including encryption of OAuth tokens at rest, server-side-only access to integration credentials, and row-level security on user data tables. No method of transmission or storage is completely secure; we cannot guarantee absolute security.

You are responsible for safeguarding your account credentials and share links. Notify us promptly at hello@wrapup.studio if you suspect unauthorized access.

International data transfers

We are based in the United States. If you access the Service from outside the U.S., your information may be transferred to, stored in, and processed in the U.S. and other countries where we or our service providers operate. These countries may have data protection laws that differ from those in your jurisdiction.

Where required, we rely on appropriate safeguards such as standard contractual clauses or provider certifications. Contact us for more information about transfer mechanisms.

Your privacy rights

Depending on where you live, you may have rights to access, correct, delete, restrict, or port personal information, and to object to or withdraw consent for certain processing. You may also have the right to opt out of "sale" or "sharing" of personal information (we do not sell personal information).

To exercise rights, email hello@wrapup.studio with the subject line "Privacy Request" and enough detail for us to verify your account. We will respond within the timeframe required by applicable law. We may deny requests where permitted, such as when disclosure would affect others' rights or we cannot verify identity.

You can delete much of your data by removing projects and clients in the app and disconnecting integrations. Account deletion requests should be sent to the contact above; during Alpha, full self-service account deletion may not yet be available.

California residents (CCPA/CPRA)

If you are a California resident, you may have additional rights under the California Consumer Privacy Act, as amended by the CPRA, including the right to know categories and specific pieces of personal information collected, the right to delete, the right to correct, and the right to opt out of sale or sharing. As stated above, we do not sell personal information and do not share it for cross-context behavioral advertising.

We collect the categories described in "Information we collect" for the business purposes in "How we use information." Submit requests to hello@wrapup.studio. We will not discriminate against you for exercising privacy rights.

European economic area, UK, and Switzerland (GDPR)

If you are in the EEA, UK, or Switzerland, we process personal data when necessary to perform our contract with you (providing the Service), based on our legitimate interests (security, analytics, product improvement, balanced against your rights), or with your consent where required (such as non-essential cookies or certain integrations).

You may lodge a complaint with your local supervisory authority. Our contact for GDPR inquiries is hello@wrapup.studio.

Children's privacy

The Service is not directed to children under 16 (or under 13 where a higher age is not required by local law). We do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact us and we will take steps to delete it.

Changes to this policy

We may update this Privacy Policy from time to time. The "last updated" date at the top will change when we do. Material changes may be communicated through the Service or by email where appropriate. Continued use after changes become effective constitutes acceptance of the revised policy.

Contact

Privacy questions, requests, or complaints: hello@wrapup.studio

See also our Terms of Use.

Disclaimers and limitation of liability

THE SERVICE AND THIS PRIVACY POLICY ARE PROVIDED FOR INFORMATIONAL PURPOSES. EXCEPT WHERE PROHIBITED BY LAW, THE SERVICE IS PROVIDED "AS IS" AND "AS AVAILABLE" WITHOUT WARRANTIES OF ANY KIND, WHETHER EXPRESS, IMPLIED, OR STATUTORY, INCLUDING IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, AND NON-INFRINGEMENT.

TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, IN NO EVENT WILL WrapUp, ITS OPERATORS, AFFILIATES, OFFICERS, DIRECTORS, EMPLOYEES, AGENTS, OR LICENSORS BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, EXEMPLARY, OR PUNITIVE DAMAGES, OR ANY LOSS OF PROFITS, DATA, GOODWILL, OR BUSINESS OPPORTUNITIES, ARISING FROM OR RELATED TO THE SERVICE OR THIS POLICY, WHETHER BASED ON WARRANTY, CONTRACT, TORT (INCLUDING NEGLIGENCE), OR ANY OTHER LEGAL THEORY, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.

TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, OUR TOTAL AGGREGATE LIABILITY FOR ALL CLAIMS ARISING OUT OF OR RELATING TO THE SERVICE OR THIS POLICY WILL NOT EXCEED THE GREATER OF (A) ONE HUNDRED U.S. DOLLARS (US $100) OR (B) THE AMOUNTS YOU PAID US FOR THE SERVICE IN THE TWELVE (12) MONTHS BEFORE THE EVENT GIVING RISE TO THE CLAIM. SOME JURISDICTIONS DO NOT ALLOW LIMITATIONS OF LIABILITY OR EXCLUSION OF CERTAIN DAMAGES; IN THOSE JURISDICTIONS, OUR LIABILITY IS LIMITED TO THE FULLEST EXTENT PERMITTED BY LAW.

Indemnification

To the maximum extent permitted by law, you agree to defend, indemnify, and hold harmless WrapUp and its operators, affiliates, officers, directors, employees, and agents from and against any claims, damages, losses, liabilities, costs, and expenses (including reasonable attorneys' fees) arising out of or related to: (a) your use of the Service; (b) your content, including client data and shared links; (c) your violation of this Privacy Policy or our Terms of Use; (d) your violation of any law or third-party right; or (e) any dispute between you and your clients or other third parties in connection with your use of the Service.

Dispute resolution

Any dispute arising out of or relating to this Privacy Policy or the Service that is not resolved informally will be resolved through binding individual arbitration rather than in court, except that either party may seek injunctive relief in court for intellectual property or unauthorized access. YOU AND WrapUp WAIVE ANY RIGHT TO PARTICIPATE IN A CLASS ACTION, CLASS ARBITRATION, OR REPRESENTATIVE ACTION.

The arbitration will be administered under the rules of a recognized arbitration provider mutually agreed by the parties, or if no agreement, the American Arbitration Association, applying the law of the State of Delaware without regard to conflict-of-law rules. The seat of arbitration will be the United States. Each party bears its own costs unless the arbitrator allocates otherwise.

If you are a consumer in a jurisdiction where mandatory arbitration or class-action waivers are unenforceable, this section does not deprive you of protections that cannot be waived by contract.